RetailEdge AI™ Security Overview
RetailEdge AI is designed for dedicated enterprise deployment. This page describes controls implemented in the application package; customer-specific Cloudflare Access, model-provider, legal, and retention settings must still be configured and approved for each tenant.
Architecture & identity
- The browser sends AI requests only to the same-origin
/api/aigateway. Free-form provider proxy requests are disabled; the gateway accepts only named RetailEdge workflows with structured payloads and builds workflow instructions server-side. - Model-provider credentials are server-side environment secrets and are never delivered to the browser.
- The Pages Functions middleware authenticates the entire application hostname, including the app shell and API routes, by validating the Cloudflare Access JWT RS256 signature, issuer, audience, timing claims, and subject. Production fails closed when Access configuration is absent.
- Verified actor subject/email metadata is carried into AI requests so operational logs can attribute gateway activity to an authenticated user without logging prompt or output bodies.
Classification & DLP controls
- Data classification is selected by the user under the customer’s policy. Requests explicitly classified Restricted are denied; Confidential processing is denied unless the tenant enables it after appropriate approval.
- Classification is not represented as a comprehensive automatic data-classification engine. Users remain responsible for choosing the correct classification.
- The gateway performs supplemental pattern screening for selected credentials, private keys, government identifiers, encoded credentials, and likely payment-card numbers. A finding returns the field/line for review before provider submission.
- Valid GS1 EAN/UPC/GTIN identifiers are excluded from payment-card detection so normal retail product identifiers are not treated as card data.
Usage & spend controls
- Production AI execution requires a configured
RETAILEDGE_USAGE_KVbinding. Without it, AI requests fail closed. - The gateway enforces per-user request-rate limits plus conservative per-user and per-tenant daily token budgets before provider calls. Budgets reserve the maximum permitted output for each request.
- Customers should additionally configure their model-provider workspace/org spending controls and alerting; application token budgets do not replace provider-level financial controls.
Data minimization & retention
- RetailEdge application code does not intentionally persist AI request or response bodies server-side.
- Generated reports saved inside the app use browser sessionStorage with an in-memory fallback; they are not written to persistent localStorage and are intended to clear with the browser session/page lifecycle.
- Gateway logs contain operational metadata such as request ID, authenticated actor, workflow, classification, character/token counts, status, and duration — not prompt or output content.
- Model-provider retention is governed by the customer’s configured provider account and commercial terms. Any tenant-facing retention label must match the actual provider agreement.
Input integrity controls
- Maximum request size and workflow input length are enforced server-side.
- CSV/TSV uploads are restricted to 5 MB and a maximum of exactly 5,000 data rows; direct XLSX parsing is intentionally disabled.
- CSV parsing runs in a browser Web Worker. Duplicate/blank headers are renamed visibly instead of silently overwriting values, row objects use a null prototype so special names such as
__proto__are handled as data, and non-blank fields beyond the declared header are rejected rather than silently discarded. - Source cell values are preserved in the parsed dataset. Only the bounded model row sample may shorten very long display values, and that shortening is explicitly marked; local aggregates continue to use the complete parsed source value.
- Wide syndicated exports are summarized within a bounded context budget using all-row aggregates plus a width-aware row sample. Users can choose which columns are included before generation.
- User-supplied blocks are explicitly delimited and are treated as untrusted data in the server system prompt to reduce prompt-injection risk.
Output integrity controls
- AI outputs are marked as AI-assisted and require human review.
- The gateway returns the provider stop reason. If a response stops because of the output token ceiling, the application marks it incomplete and disables save/copy/export actions for that deliverable.
- Numeric guidance instructs the model not to fabricate unsupported values and to expose formulas, assumptions, units, and confidence when estimates are supported.
Web application controls
- Security headers include HSTS, frame denial, nosniff, referrer restrictions, browser-permission restrictions, and a Content Security Policy with self-hosted scripts/workers and no inline JavaScript.
- CSV previews and session-report rendering use DOM text nodes rather than injecting uploaded/saved content as HTML.
- API responses use
Cache-Control: no-store. The service worker does not cache HTML, authenticated API traffic, or business content; app navigation is network-only so access policy can be re-evaluated.
Procurement note: This software package does not claim SOC 2, ISO 27001, PCI DSS, HIPAA, penetration-test certification, or any certification that has not actually been obtained. Before handling a customer’s Confidential information, execute the required enterprise agreement/DPA, approve subprocessors/model-provider terms, configure SSO/Access, usage budgets and retention, set provider-level spend controls, and complete the customer’s security review.